Closed snyk-bot closed 2 years ago
A dependency change in this PR is introducing new install scripts to your install step.
Package | Script field | Location |
---|---|---|
protobufjs@6.11.3 (upgraded) | postinstall |
package.json via @grpc/proto-loader@0.6.13 |
Issue | Status |
---|---|
Did you mean? | β no new possible package typos |
Install scripts | β οΈ 1 new install script detected |
Telemetry | β no new telemetry |
Troll package | β no new troll packages |
Malware | β no new malware |
Native code | β no new native modules |
Powered by socket.dev
Snyk has created this PR to upgrade @grpc/proto-loader from 0.6.5 to 0.6.13.
The recommended version fixes:
SNYK-JS-PROTOBUFJS-2441248
Why? Proof of Concept exploit, CVSS 8.2
(*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: @grpc/proto-loader
protobufjs
dependency to "^6.11.3" (#2131 contributed by @ ocofaigh)long
dependency to 4.x (#2114)long
to 4.x or 5.x (#2112)long
library to version 5 to fix some TypeScript type compatibility issues (#2110)Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:![](https://api.segment.io/v1/pixel/track?data=eyJ3cml0ZUtleSI6InJyWmxZcEdHY2RyTHZsb0lYd0dUcVg4WkFRTnNCOUEwIiwiYW5vbnltb3VzSWQiOiJjMmNjMzc4OC1lMDZkLTQwNGQtYThlMC04OTQ1MWRhYzdiZTAiLCJldmVudCI6IlBSIHZpZXdlZCIsInByb3BlcnRpZXMiOnsicHJJZCI6ImMyY2MzNzg4LWUwNmQtNDA0ZC1hOGUwLTg5NDUxZGFjN2JlMCJ9fQ==)
π§ View latest project report
π Adjust upgrade PR settings
π Ignore this dependency or unsubscribe from future upgrade PRs